IBM Security Bulletin: IBM Content Navigator is affected by an XML External Entity Injection (XXE) vulnerability

IBM Content Navigator has addressed the following vulnerability.

CVE(s): CVE-2018-1364

Affected product(s) and affected version(s):

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22012595
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137449

The post IBM Security Bulletin: IBM Content Navigator is affected by an XML External Entity Injection (XXE) vulnerability appeared first on IBM PSIRT Blog.

Affected IBM Content NavigatorAffected Versions
IBM Content Navigator2.0.3
IBM Content Navigator3.0.2
IBM Content Navigator3.0.3


from IBM Product Security Incident Response Team http://ift.tt/2DB5rOs